CVE-2026-0270
Cortex XSOAR: Path Traversal Vulnerability
Severity
Medium 4.8
CVSS 4.0
Exploited
Not listed
EPSS
0.002
9.9th percentile
Discovered by
Vendor
Published by the vendor
Published
Jun 10, 2026
Assigned by palo_alto
Description
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XSOAR | SIEM & Log Management | cna-assigner |
Vendor-reported affected versions (2)
- Palo Alto Networks · Cortex XSOAR
- Palo Alto Networks · Cortex XSOAR
Credit
Palo Alto Networks thanks the internal security team for discovering and reporting this issue.
Vendor remediation
VERSION MINOR VERSION SUGGESTED SOLUTION Cortex XSOAR 8.13 on Linux 8.13.0 Upgrade to 8.13.0.11 or later.